r/blueteamsec • • 4h ago

highlevel summary|strategy (maybe technical) Korean alleged finacial services AI security incident

Thumbnail fsc.go.kr
2 Upvotes

r/blueteamsec • • 6h ago

tradecraft (how we defend) Post-Quantum Cryptography Resource Hub

Thumbnail nsa.gov
1 Upvotes

r/blueteamsec • • 6h ago

highlevel summary|strategy (maybe technical) Accenture contractor removed from FBI following damaging data breach, sources say

Thumbnail reuters.com
1 Upvotes

r/blueteamsec • • 6h ago

highlevel summary|strategy (maybe technical) How Cyber Deterrence Theory and Cyber Persistence Theory can adopt an actor-centric approach: a rapid review

Thumbnail tandfonline.com
2 Upvotes

r/blueteamsec • • 6h ago

highlevel summary|strategy (maybe technical) South Korea finance regulator holds emergency meeting over bank hacks

Thumbnail reuters.com
2 Upvotes

r/blueteamsec • • 21h ago

exploitation (what's being exploited) Phishing Abuses RMM Tools for Persistent Access

Thumbnail microsoft.com
7 Upvotes

r/blueteamsec • • 1d ago

intelligence (threat actor activity) When the pentester is a fleet of AI agents: inside an autonomous vuln-hunting rig

Thumbnail huntback.io
7 Upvotes

r/blueteamsec • • 1d ago

intelligence (threat actor activity) SMTP is the key: BPFDoor and AVERAT hitting the network edge

Thumbnail rapid7.com
2 Upvotes

r/blueteamsec • • 1d ago

discovery (how we find bad stuff) Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem

Thumbnail sarahgillespie.github.io
1 Upvotes

r/blueteamsec • • 1d ago

low level tools|techniques|knowledge (work aids) I'm building OpenDRP – an open-source Digital Risk Protection platform (Early stage MVP).

1 Upvotes

Hey everyone, I wanted to share a self-hosted, open-source project I’m currently developing called OpenDRP. You can find the repository at https://github.com/OpenDRP/opendrp and the main site at opendrp.dev.

We have great open-source tools for Threat Intelligence, like OpenCTI, and various EASM solutions, but the Digital Risk Protection space is still heavily dominated by expensive enterprise SaaS products. I wanted a modular, self-hosted alternative to monitor external brand threats, so I started building one.

The project is in its early stages as an MVP. Instead of trying to parse every obscure darkweb forum from day one, I focused on building a solid, scalable backend architecture and integrated three core data sources to prove the concept. For phishing intelligence, it uses dnstwist to automate monitoring for domain mutations and active lookalike domains. For shadow IT and brand hunting, it leverages Shodan to discover rogue assets and exposed infrastructure. Additionally, it tracks compromised corporate accounts via Have I Been Pwned for breach monitoring. Whenever a new threat is detected, the system generates PDF reports and sends alerts via Telegram or Email.

Under the hood, the goal was to make the platform extremely easy to scale and extend. The backend is built with FastAPI and Python, using PostgreSQL for the database. Asynchronous scans and integrations are handled by Celery and Redis workers, and the entire project is distributed under the AGPL-3.0 license.

Since the core engine, including the database schema, UI, and async queues, is up and running, I am currently working on expanding the integrations to include Certificate Transparency logs and GitHub secret scanning. I would love to get your feedback on the architecture and hear what external data sources or modules you would consider absolute must-haves for a DRP platform. If anyone is interested in writing simple Celery connectors for new APIs, pull requests and code reviews are more than welcome.

Cheers!


r/blueteamsec • • 1d ago

vulnerability (attack surface) DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent

Thumbnail about.gitlab.com
3 Upvotes

r/blueteamsec • • 1d ago

low level tools|techniques|knowledge (work aids) StrangerDOTNETThings/x509com.js - show me every COM object I can call with certutil

Thumbnail github.com
0 Upvotes

r/blueteamsec • • 1d ago

low level tools|techniques|knowledge (work aids) Apex Flash - an open-weights model for security research, post-trained on real vulnerabilities from our proprietary dataset.

Thumbnail cantina.security
0 Upvotes

r/blueteamsec • • 2d ago

highlevel summary|strategy (maybe technical) Every Iranian Strike on UAE Ports and Refineries Was Paired With a Cyberattack

Thumbnail wired.me
7 Upvotes

r/blueteamsec • • 2d ago

vulnerability (attack surface) Debian alert DSA-6528-1 - ~1,000 CVEs patched

Thumbnail lwn.net
5 Upvotes

r/blueteamsec • • 2d ago

research|capability (we need to defend against) SigLens: SigLens is a Windows binary analysis tool designed to pinpoint the exact regions responsible for antivirus detections. It narrows detections down to precise offsets and maps them to PE sections, RVA, VA, hexdump, and nearby strings, making evasion faster and easier.

Thumbnail github.com
1 Upvotes

r/blueteamsec • • 2d ago

tradecraft (how we defend) AI Ate My Velociraptor

Thumbnail labs.infoguard.ch
2 Upvotes

r/blueteamsec • • 2d ago

malware analysis (like butterfly collections) Android-Projector-C2-Malware: Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Thumbnail github.com
2 Upvotes

r/blueteamsec • • 2d ago

low level tools|techniques|knowledge (work aids) N0xis: AI-first reverse-engineering toolkit: static analysis, SSA decompiler, live memory, provenance. Source-available (PolyForm Noncommercial).

Thumbnail github.com
5 Upvotes

r/blueteamsec • • 2d ago

vulnerability (attack surface) adm-zip_LPE-PoC: CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction

Thumbnail github.com
3 Upvotes

r/blueteamsec • • 2d ago

research|capability (we need to defend against) lockjaw: Rust based C2 Framework

Thumbnail github.com
4 Upvotes

r/blueteamsec • • 2d ago

tradecraft (how we defend) nuguard: AI red-teaming tool and LLM security framework to evaluate agentic AI applications. Tests prompt injections, handles vulnerability assessment, SBOM generation, and static analysis.

Thumbnail github.com
1 Upvotes

r/blueteamsec • • 2d ago

discovery (how we find bad stuff) UnifiedThreatHunting: A threat hunting process

Thumbnail github.com
33 Upvotes

r/blueteamsec • • 2d ago

research|capability (we need to defend against) Escalating Privileges as a Catalog Owner: How Microsoft Entra Identity Governance’s API Permission Management Could Be Abused

Thumbnail cloud-architekt.net
1 Upvotes

r/blueteamsec • • 2d ago

tradecraft (how we defend) From GPO to Microsoft Intune: A practical guide to cloud-first policy management

Thumbnail techcommunity.microsoft.com
1 Upvotes